Cisco has warned of two zero-day vulnerabilities in its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) platforms that are currently under active exploitation. With one of the flaws carrying a critical CVSS 9.9 rating, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) swiftly responded by issuing an emergency mitigation directive requiring federal agencies to patch or block exploitation within 24 hours. The urgency of the alert underscores the severe threat to enterprise and government networks globally.

The Key Threats: What’s Vulnerable and How Attackers Are Abusing It

Cisco identified two zero-day issues:

  • CVE-2025-20333 (CVSS score: 9.9): An improper validation of user-supplied input in HTTP(S) requests that could allow an authenticated remote attacker (with valid VPN credentials) to execute arbitrary code as root via crafted HTTP requests.
  • CVE-2025-20362 (CVSS score: 6.5): Also stemming from improper input validation, this flaw lets an unauthenticated remote attacker access restricted URL endpoints without authentication, again via crafted HTTP requests.

Cisco confirmed it is aware of attempted exploitation of both vulnerabilities, though it did not name who is behind the attacks or their scope. Analysts suspect that attackers may be chaining the two flaws—first bypassing authentication, then escalating privileges to execute malicious code on vulnerable appliances.

These vulnerabilities affect the VPN web server component of Cisco ASA and FTD installations. Because such appliances often sit at the edge of trusted networks, successful exploitation can offer deep footholds into organizational infrastructure.

CISA Steps In: Emergency Directive and Threat Attribution

In response to the active threat, CISA issued Emergency Directive ED 25-03, mandating that U.S. federal agencies immediately identify, analyze, and mitigate potential compromises associated with the ASA vulnerabilities.

CISA also added the two zero-days to its Known Exploited Vulnerabilities (KEV) catalog, compelling covered entities to act within 24 hours.

According to the agency, the campaign is “widespread” and involves unauthenticated remote code execution and even manipulation of a device’s read-only memory (ROM) to maintain persistence across reboots or firmware upgrades.

The group behind the attacks is linked to a threat cluster called ArcaneDoor—also known by identifiers such as UAT4356 or Storm-1849. This actor had been previously spotted targeting perimeter appliances from multiple vendors (including Cisco), delivering malware such as Line Runner and Line Dancer.

CISA noted that ArcaneDoor “has demonstrated a capability to successfully modify ASA ROM at least as early as 2024.” If confirmed, this reflects a high degree of sophistication and deep exploitation.

Cisco also pointed out that the same vulnerabilities may affect certain versions of Cisco Firepower, though the Secure Boot feature in Firepower can detect ROM tampering, offering some protection against the most severe persistence techniques.

To assist defenders, Cisco credited cooperation from multiple cybersecurity agencies worldwide, including the Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security, U.K. National Cyber Security Centre, and others

Background & Risk Landscape

Zero-days in networking devices—and especially in firewall or VPN appliances—are among the most dangerous vectors in enterprise security. These systems are often assumed to be hardened and trusted, but when compromised, they allow attackers to bypass defenses, move laterally, and remain undetected for long periods.

Past campaigns by ArcaneDoor and similar actors have demonstrated how adversaries target perimeter infrastructure—routers, firewalls, VPN gateways—because they act as chokepoints for enterprise traffic. By compromising those devices, attackers can monitor, intercept, and manipulate traffic as well as gain privileged access to internal networks.

The fact that attackers are chaining vulnerabilities—starting with authentication bypass or information disclosure and moving to root-level code execution—illustrates the layered nature of modern intrusion tactics. Moreover, the ability to tamper with ROM or firmware enables persistence that survives reboot cycles or even firmware patches if defenders are not vigilant.

Given the global reach of Cisco’s ASA and FTD appliances, the potential impact of such zero-days is vast—and not limited to government networks. Critical infrastructure, large enterprises, and service providers are all at risk if patches or mitigations are not applied promptly.

Expert Insight & Defensive Measures

Cybersecurity practitioners emphasize speed, monitoring, and defense-in-depth as key responses:

  • Patching & Mitigation: Organizations should apply the security updates provided by Cisco as soon as possible. Where patching is not immediately feasible, mitigation steps such as blocking HTTP(S) access to the VPN web component can reduce risk.
  • Network Monitoring & Intrusion Detection: Deploying robust monitoring of traffic to and from the VPN or ASA device, with anomaly detection or behavior-based alerts, may help spot exploitation attempts early.
  • Segment & Isolate: Restrict access to management interfaces from trusted endpoints only; network segmentation can reduce the blast radius of a compromised appliance.
  • Firmware Integrity Checks: Periodically verify ROM or firmware integrity to detect tampering, especially if devices support secure boot or cryptographic checks.
  • Incident Readiness: Given CISA’s directive and the known exploitation, organizations should presuppose they may already be under threat and conduct threat hunts or code audits on ASA/FTD deployments.

One security consultant commented (anonymously):

“When a firewall or VPN gateway is compromised at root level, defending becomes almost impossibly reactive. The best time to act is before compromise. Speed and vigilance matter more than any single tool.”

Conclusion

The emergence of two actively exploited zero-days in Cisco’s ASA and FTD platforms is a stark reminder of how critical perimeter infrastructure remains a prime target for sophisticated threat actors. With CISA’s emergency directive and Cisco’s alerts, the cybersecurity community is on high alert. Organizations must move quickly—patching, monitoring, and hardening—to prevent intrusion and mitigate damage. The next few days will be crucial in determining how many networks fall, and how many survive through preparedness.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *